Privacy policy
What we collect when you use Alcoven, why, where it is kept, and your rights over it.
In short
- Deep Node Studios Yazılım ve Teknoloji Limited Şirketi, in İstanbul, is responsible for your personal data in Alcoven.
- We collect what running Alcoven needs: your account, what you and your agents write on projects, and records of agent use for billing.
- The app and your projects are stored with Amazon Web Services in Frankfurt. Paddle handles payments as our merchant of record.
- We don’t sell your data, use it for advertising, or train models on it. alcoven.co sets no cookies and runs no analytics.
- You can ask to see, correct, export or delete your data, or object to how we use it, at [email protected].
This summary helps you read. The numbered sections below are the policy.
1. Who is responsible for your data
DEEP NODE STUDİOS YAZILIM VE TEKNOLOJİ LİMİTED ŞİRKETİ, FENERBAHÇE MAH. İĞRİP SK. NO: 13 İÇ KAPI NO: 1, KADIKÖY / İSTANBUL, Türkiye (“we”, “us”) is responsible for the personal data of the people who use Alcoven at app.alcoven.co and visit alcoven.co. We are its controller under the EU General Data Protection Regulation (GDPR), and its data controller (veri sorumlusu) under Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK).
For anything about your data, write to [email protected].
The team that owns a project decides what goes into it. When a project holds other people’s personal data, for example a client’s name in a document, we process that data for the team, to run Alcoven.
2. What we collect, and why
Your account
Your name, your email address and your password. Amazon Cognito keeps the password, and our servers keep no copy of it. We also keep the teams and projects you belong to, your role and permissions on each, and anything you write about yourself on a project.
Why: to create your account, sign you in, and show the people on your projects who you are. Legal basis: our contract with you.
What you and your agents write
The content of your projects: the brief, documents and the files you upload, tasks, notes, your conversations with the agent in the app, the passages it cites from the web, and every past version. Each project’s history records who changed what, when, and from where (the app, git or an AI app).
Why: this is the service. We keep it, and show it to the people and agents on the project. Legal basis: our contract with you.
Access for your own tools
The git tokens you create, the AI apps you allow to open a project (their name, when you allowed them, and their access tokens), and when each person cloned, fetched or pulled a project, so the project can show what changed since.
Why: to let your tools in, and to keep the record straight. Legal basis: our contract with you.
Agent use
For each call the app makes to a model: the project and the person it was for, the model, the number of tokens in and out, the cost and the time. The same for each web search, and the conversation keeps the links of the pages the agent searched and opened, never their text.
Why: to count included use, apply budgets, bill use above the included amount, and keep costs in check. Legal basis: our contract with you, and our legitimate interest in preventing abuse.
Payments
Paddle collects your payment details, billing address and any tax number itself, as merchant of record. We never see your card number. Paddle sends us what we need to run the team’s plan: the customer’s name and email address, the plan, the number of seats, the state of the subscription, and the invoices.
Why: to give the team the plan it paid for, and to show its invoices. Legal basis: our contract with you, and our legal duty to keep financial records.
Messages you send us
What you write to [email protected], and feedback you send from the app, with the page you were on and your browser’s name and version.
Why: to answer you and to improve Alcoven. Legal basis: our contract with you when you ask for help with Alcoven, otherwise our legitimate interest in answering and improving it.
Technical records
When something fails, our servers record the error, which can include identifiers for your account, your team or a project.
Why: to keep Alcoven working and secure. Legal basis: our legitimate interest in running a secure service.
The website
alcoven.co sets no cookies and runs no analytics or advertising scripts. Vercel, which hosts it, and Cloudflare, which carries its traffic, process your IP address and the details of each request to deliver the pages and protect the site. Two pages we share by link only, a slide deck and a template, load their typeface from Google Fonts, so opening them sends your IP address to Google.
Legal basis: our legitimate interest in delivering and protecting the site.
The waitlist, now closed
Before sign-up opened, alcoven.co had a waitlist, stored with Supabase: an email address, the kind of project, and any answers to the optional questions that followed. The waitlist is closed. We keep those entries only to send one note that sign-up is open, and then we delete them, answers included.
Legal basis: your consent, given when you joined. You can withdraw it at any time by writing to us, and we delete your entry.
3. The agent in the app, and AI models
We don’t train models on your data. The agent in the app runs on Amazon Bedrock, and AWS says that neither AWS nor the model providers use inputs to or outputs from Bedrock to train any model, and that inputs and outputs are not shared with the model providers (Amazon Bedrock FAQs).
When you ask the agent something, the parts of the project it needs go to the model you chose. To keep each project easy to search, the app also sends new and changed text to a model in Frankfurt, which summarises it for the project’s index. Where a request is processed depends on the model:
| Where it is processed | Models |
|---|---|
| Frankfurt (eu-central-1) | Qwen3 235B (the default), MiniMax M2.5, GLM 4.7 Flash, gpt-oss 120B, gpt-oss 20B, Nemotron 3 Super, Devstral 2 |
| AWS regions in the EU | Nova Pro |
| Any AWS region worldwide | Kimi K3, Nova 2 Lite and the Claude models |
Requests routed to another region travel on AWS’s own network, encrypted, and content Bedrock stores is kept at rest in Frankfurt (AWS on cross-region inference).
When the agent searches the web, the search terms it writes go to AWS’s web search, which we run in Ireland (eu-west-1). The pages it opens are fetched by our servers in Frankfurt. The project keeps only the passages the agent cites, with their links.
4. Your own AI tools
When you open a project from your own AI app over MCP, or clone it with git into a folder where a coding agent works, what you open goes to that tool and its provider. Your own agreement with them, and their privacy terms, apply to it. For that work, we run no model.
5. Cookies
alcoven.co sets no cookies. The app at app.alcoven.co uses these:
| Cookie | What it is for |
|---|---|
alcoven_session30 days | Keeps you signed in. |
alcoven_signup1 hour | Holds your sign-up, sealed so only our server can read it, while you confirm your email address. It is removed once used. |
alcoven_challenge10 minutes | Holds a sign-in step while you set a new password. |
alcoven-leftalcoven-right-w1 year | Remember how you laid out a project’s panes. |
alcoven-theme1 year | Remembers Light, Dark or Match my system. |
AWSALBAWSALBCORS7 days | Set by AWS’s load balancer, to send your requests to the same server. |
The app also keeps a few display choices in your browser’s own storage, such as which folders you folded. They stay on your device.
All of these are needed for the app to work, or to remember a choice you made. There are no analytics or advertising cookies. When you pay, Paddle’s checkout runs in a frame from Paddle and may set its own cookies, as Paddle’s privacy notice describes. You can delete cookies in your browser at any time; deleting alcoven_session signs you out.
6. Where your data is kept, and who handles it
These providers process personal data for us:
- Amazon Web Services (AWS) runs the app, its database (encrypted at rest), its backups, our server logs and the sign-in (Amazon Cognito), in Frankfurt, Germany (eu-central-1). Cognito also sends the emails with your sign-up and password codes. Amazon Bedrock runs the models (section 3), and AWS’s web search runs in Ireland (eu-west-1).
- Vercel hosts alcoven.co, and Cloudflare carries its traffic.
- Google hosts our email.
- Supabase held the waitlist (section 2).
Paddle sells the paid plans as our merchant of record. It handles the sale, the subscription and payments, tax and invoicing, and decides for itself how it handles the data it collects, as Paddle’s privacy notice explains.
We also share personal data:
- with the people and agents on your projects, who see what you write there and who changed what;
- with professional advisers, such as lawyers and accountants, who must keep it confidential;
- with authorities, when the law requires it, or to protect people’s rights and safety;
- with a buyer or successor, if our company is merged or sold, and we will tell you if that happens.
We don’t sell personal data or share it for advertising.
7. Transfers abroad
Alcoven runs outside Türkiye, so using it transfers your personal data abroad:
- to AWS, in Germany and Ireland, and in other AWS regions worldwide for the models in the last row of the table in section 3;
- to Paddle;
- to Vercel, Cloudflare and Google, which run their services in many countries, including the United States;
- for the waitlist, to Supabase.
Each of them processes it under the data protection terms it publishes.
8. How long we keep it
- Your account: while you have one. When you ask us to delete it, we delete your account details. What you wrote on projects stays on them under your name, as part of each project’s history, for as long as the project is kept.
- Projects: as long as the team keeps them. A closed project stays on our systems until the team asks us to delete it.
- Agent use and billing records: as long as tax and accounting law requires.
- Server logs: 30 days.
- Database backups: 7 days, so deleted data is gone from them within 7 days.
- Messages and feedback: as long as we need them to answer you and follow up.
- The waitlist: until the note that sign-up is open has gone out.
When we no longer need personal data, we delete it or make it anonymous.
9. How we protect it
The database is encrypted at rest, and everything sent to and from Alcoven travels over HTTPS. Only the people who run Alcoven can reach its production systems. Passwords stay with Amazon Cognito. If a breach puts your personal data at risk, we will tell you and the authorities as the law requires.
10. Your rights
You can ask us to:
- tell you whether we hold personal data about you, and give you a copy;
- correct it;
- delete it;
- give it to you in a form you can take elsewhere (you can also clone or download any project you can read);
- limit how we use it, or stop using it where we rely on our legitimate interests;
- tell the providers we shared it with about a correction or deletion.
Where we rely on your consent, you can withdraw it at any time. Under the KVKK, you can also:
- ask what we use your data for, and whether we use it only for that;
- learn who receives it, in Türkiye or abroad;
- object to a result that goes against you when it comes only from software analysing your data;
- claim compensation if unlawful processing harms you.
Software alone never makes a choice about you that has legal or similarly significant effects.
How to ask: write to [email protected] from the email address on your account, or tell us how we can check it is you. We answer free of charge, as soon as we can: within one month under the GDPR, and within 30 days under the KVKK. We may keep what the law requires us to keep, and what you wrote on a project stays in that project’s history for the team.
Complaints: you can complain to a data protection authority: in the EU or EEA, the one where you live or work (list of authorities); in the UK, the Information Commissioner’s Office; in Türkiye, the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu, kvkk.gov.tr). Under the KVKK, you write to us first; you can then complain to the Board within 30 days of our answer, or within 60 days of your request if we have not answered.
11. Children
Alcoven is meant for people aged 16 or over, and we don’t knowingly collect data from anyone younger. If you believe someone under 16 has given us personal data, write to us and we will delete it.
12. Changes to this policy
We may update this policy. We publish each version here with its date, and when a change matters to you, we tell you by email or in the app before it applies. The terms and the refund policy sit beside it.
13. Contact
Write to [email protected], or by post to DEEP NODE STUDİOS YAZILIM VE TEKNOLOJİ LİMİTED ŞİRKETİ, FENERBAHÇE MAH. İĞRİP SK. NO: 13 İÇ KAPI NO: 1, KADIKÖY / İSTANBUL, Türkiye.